Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

H. D. Moore

From Wikipedia, the free encyclopedia
American businessman (born 1981)

H. D. Moore
Born1981 (age 43–44)
NationalityAmerican
Occupation(s)Information security researcher andprogrammer
Known forMetasploit
Websitehdm.io

HD Moore is an Americannetwork security expert,open source programmer, andhacker. He is the founder of theMetasploit Project and was the main developer of the Metasploit Framework, apenetration testingsoftware suite.

Moore is currently the co-founder and chief technical officer of runZero, Inc,[1] a provider of cyber assetattack surface management software andcloud solutions. The company was originally founded in 2018 as Rumble, Inc and renamed to runZero, Inc. in 2022.[2]

Prior to starting runZero, Moore served as the vice president of research and development at Atredis Partners,[3] the chief research officer atBoston,Massachusetts-based security firmRapid7, and remained the chief architect of the Metasploit Framework until his departure from Rapid7 in 2016.[4]

Information security work

[edit]

Moore developed security software utilities for theUnited States Department of Defense as a teenager,[5][better source needed] and founded the Metasploit Project in the summer of 2003 with the goal of becoming a public resource for exploit code research and development.[6]

He is known for his work inWarVOX, AxMan, the Metasploit Decloaking Engine and the Rogue Network Link Detection Tools,[7] and started a "Month of Browser Bugs" (MoBB) initiative in 2006[8] as an experiment in fast-pacedvulnerability discovery withfull disclosure. This started theMonth of Bugs project meme, and resulted a number ofweb browserpatches and improved security measures.

Moore has discovered, or been involved in the discovery of, a number of critical security vulnerabilities.[9][10]

Metasploit Framework

[edit]

The Metasploit Framework is a development platform for creating security tools andexploits. The framework is used by network security professionals to perform penetration testing, system administrators to verify patch installations, product vendors to perform regression testing, and security researchers worldwide. The framework is written in theRubyprogramming language and includes components written inC andassembly language.[11] In October 2009, the Metasploit project was acquired by Rapid7.[12] While the Metasploit Framework continues to be free, Rapid7 has added commercial editions.[13] With the acquisition of the project, HD Moore becamechief security officer at Rapid7, and laterchief research officer, while remaining chief architect of Metasploit.

WarVOX

[edit]
Main article:WarVOX

WarVOX is a software suite for exploring, classifying, and auditing telephone systems. Unlike normalwardialing tools, WarVOX processes the raw audio from each call and does not use amodem directly. This model allows WarVOX to find and classify a wide range of interesting lines, including modems, faxes, voice mail boxes,PBXs,loops, dial tones,IVRs, and forwarders usingsignal processing techniques.

AxMan

[edit]

AxMan is anActiveXfuzzing engine. The goal of AxMan is to discover vulnerabilities inCOM objects exposed throughInternet Explorer. Since AxMan is web-based, any security changes in the browser will also affect the results of the fuzzing process.

Metasploit Decloaking Engine

[edit]

The Metasploit Decloaking Engine is a system for identifying the realIP address of a web user, regardless ofproxy settings, using a combination of client-side technologies and custom services. No vulnerabilities are exploited by this tool. A properly configured Tor setup should not result in any identifying information being exposed.

Rogue Network Link Detection Tools

[edit]

The Rogue Network Link Detection Tools are designed to detect unauthorized outbound network links on large corporate networks. These tools send spoofedTCP SYN andICMP Echo Requests with the original destination IP encoded into the packet, which can then be read back out by an external listening host.

Reception

[edit]

Moore's work has gained him both praise and antagonism in the industry. Companies such asMicrosoft have credited him with discovering vulnerabilities, yet some criticism of Metasploit and similar tools, due to their capacity for criminal use (rather than just offensive security), has fallen upon Moore himself. Moore has been warned by US law enforcement about his involvement in the Critical.IO scanning project.[14]

References

[edit]
  1. ^"Meet our leadership team".runZero. RetrievedJune 10, 2024.
  2. ^"Rumble Network Discovery is now runZero!", Aug 8, 2022, www.runzero.com/blog/introducing-runzero/
  3. ^"Team - Atredis Partners", May 14, 2019, www.atredis.com/team
  4. ^"HD Moore Chief Security Officer, Rapid7". RSA Conference. Archived fromthe original on December 13, 2014. RetrievedNovember 15, 2014.
  5. ^Jackson Higgins, Kelly (September 28, 2006)."HD Moore Unplugged".Dark Reading. Information Week. RetrievedJuly 15, 2015.Of course, being the industry's most famous white hat hacker also makes you a popular target
  6. ^Biancuzzi, Federico."Metasploit 3.0 day". Security Focus. RetrievedNovember 15, 2014.
  7. ^http://hdm.io/ HD Moore’s personal page
  8. ^"A Month of Browser Bugs", August 3, 2006, www.schneier.com
  9. ^Keizer, Gregg (October 16, 2007)."HD Moore takes iPhone exploits public". ComputerWorld. RetrievedApril 27, 2017.
  10. ^Nachneir."HD Moore Unveils Major UPnP Security Vulnerabilities". Watchguard Security. RetrievedApril 27, 2017.
  11. ^Metasploit project page
  12. ^Rapid7 Acquires Metasploit
  13. ^Product page for commercial Metasploit editions
  14. ^Brewster, Tom (May 29, 2014)."US cybercrime laws being used to target security researchers".The Guardian. RetrievedNovember 15, 2014.

Further reading

[edit]
  • The Hacker Diaries by Dan Verton, Mar 26, 2002,ISBN 0-07-222364-2, pp. 166–181
  • Darknet Diaries, Jack Rhysider, Apr 05, 2022, Podcast, Episode 114:HD, https://darknetdiaries.com/episode/114

External links

[edit]
Retrieved from "https://en.wikipedia.org/w/index.php?title=H._D._Moore&oldid=1279640446"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp